Back to home
Governance & Beyond · Insights

The DPDP Act, 2023 — in one everyday example

No legal terms to start with. Four everyday situations, and everything the law changes about each one.

This is just one illustration — the same law plays out the same way across sectors. Pick another everyday example:

Forget the Act for a second. Here are the two people this law is actually about — you've been both, depending on the day.

Data Principal

Ramesh

A patient booking a blood test. His data. His say in what happens to it.

Data Fiduciary

ABCD Diagnostics

The lab collecting Ramesh's data. Now legally responsible for it.

Ramesh and ABCD Diagnostics are fictional, used only to illustrate how the Act works. Any resemblance to a real person or business is coincidental and unintended.

Here's what the law actually requires, step by step:

AD
LAB
Step 1 — Asking

Before taking his sample, the lab must clearly tell Ramesh what it's collecting (name, phone, test results) and exactly why — not buried in fine print, in plain language he can actually read.

R
RAMESH
Step 2 — Agreeing

Ramesh gives his Consent — a real yes, not a pre-ticked box he scrolled past. He could just as easily have said no to any part he wasn't comfortable with.

AD
LAB
Step 3 — Using it, only for that

The lab can use Ramesh's data to run the test and share the report — nothing more. It can't quietly sell his phone number to a pharmacy or a health insurance marketer without asking him separately.

AD
LAB
Step 4 — Keeping it safe

A blood test report is high-risk data — so the lab can't just email it as an open attachment. It should send it password-protected, because that's what "reasonable" security looks like for something this sensitive. And if its systems are ever hacked and data leaks anyway, it must tell both Ramesh and the government's Data Protection Board — quickly, not months later.

R
RAMESH
Step 5 — Staying in control

Months later, Ramesh can ask the lab what it still holds on him, get a wrong entry corrected, or ask it to delete his data once he no longer needs their service.

R
RAMESH
Step 6 — If something goes wrong

If the lab ignores any of this, Ramesh can complain — first to the lab, then to the Data Protection Board, which can fine the lab up to ₹250 crore for serious violations.

That's the whole law, really — one relationship, two sides, six moments. Here's what to remember depending on which side you're on:

If you're the Data Principal

Ramesh's checklist

  • You can say no, or say yes only to part of it.
  • You can ask what's held about you, anytime.
  • You can get it corrected or deleted.
  • You have somewhere to complain if ignored.
If you're the Data Fiduciary

ABCD's checklist

  • Ask plainly, before you collect.
  • Use data only for what you asked permission for.
  • Protect it, and report leaks fast.
  • Be ready to show, correct, or erase on request.

Eight words, if you need them

Data Principal
The person the data belongs to — Ramesh, Sunita, Arjun, or Kavya, in these stories.
Data Fiduciary
The organisation deciding why and how the data is used — the lab, the NBFC, the school, the agency.
Data Processor
A vendor handling data on a Fiduciary's behalf, like a credit bureau — bound by contract to protect it the same way.
Verifiable Parental Consent
For a child's data, the Act requires a parent or guardian to consent on their behalf, in a way the Fiduciary can verify.
Cross-Border Transfer
Sending personal data outside India — generally allowed, except to countries the government specifically restricts.
Data Protection Board
The government body a Data Principal can complain to, and which can fine a Fiduciary.
Data Breach
Any leak, loss, or unauthorised access to personal data that the Fiduciary must report.